MapFlow vs the Alternatives
The sovereign-secure alternative to failed "lift and shift" migrations. How MapFlow compares to Arcus Spreadsheet Field Mapping and MS Access Datachecker — the tools councils have been forced into when modern, cloud-native ETL was procedurally blocked.
The AI difference: MapFlow's AI Mapping Assistant creates complete, confidence-scored field mappings from a single natural-language request. Reverse-engineering with candidate records achieves 95%+ confidence by comparing actual source↔destination values side-by-side. What takes weeks of manual data discovery is completed in minutes.

A Replacement for Arcus Datachecker
MapFlow is the modern replacement for the Arcus MS Access Datachecker. Every difference in the comparison below comes down to one thing: a modern Platform-as-a-Service, versus Microsoft Office. Datachecker is a genuinely capable tool that has served councils well — but it has reached the hard limit of Microsoft Access, an engine first released in 1992. No amount of expert maintenance can move that ceiling; only a change of architecture can.
You're driving around in a modern car — while data migration specialists are being asked to deliver the same journey in a Model T Ford.
Everyone on the council team streams 4K video to the phone in their pocket, asks an AI to draft their emails, and unlocks their front door from another country. Meanwhile, the people trusted with moving millions of citizen records are handed a desktop file format that launched in 1992 — older than the smartphone, the smart speaker, and the streaming service you use every day. Nobody would expect a Model T to win a modern commute. Nobody should expect a 30-year-old file database to carry a modern data migration. MapFlow is simply the modern vehicle.
How long is 30 years in technology?
The Jet/ACE engine that powers MS Access was designed before most of the technology your council relies on today even existed. To grasp just how long ago that is, here are some of the things that happened in the years since Access was built.
1992
Microsoft Access 1.0 ships. Text messages (SMS) are sent for the first time. Most homes connect to the internet over a dial-up modem that screeches for a minute to load a single page.
1995
Windows 95 launches with the Start button. Toy Story — the first fully computer-animated film — hits cinemas. DVDs are introduced.
1997
DVDs go on sale to the public. The first ringtones are sold for mobile phones. Netflix launches as a DVD-by-post service.
1998
Google is founded. The candy-coloured iMac launches. Most people still buy music on CD.
2000
The first camera phone ships. The PlayStation 2 launches and becomes the must-have Christmas gift.
2001
The iPod launches — '1,000 songs in your pocket' was revolutionary. Wikipedia goes online.
2004
Facebook launches — originally only for university students.
2005
YouTube launches. The first video ever uploaded is literally called 'Me at the zoo'.
2006
Twitter launches. The first 'tweet' is sent.
2007
The iPhone launches — the smartphone as we know it did not exist when MS Access's engine was designed.
2008
Spotify launches. The first Android phone goes on sale.
2010
The iPad launches. Instagram launches — and photography has never been the same.
2011
Snapchat launches — photos that disappear.
2014
Alexa and the smart speaker arrive in ordinary homes. You can now pay for coffee with your phone.
2016
Pokémon GO has millions of people wandering the streets chasing virtual creatures in the real world.
2019
People stream entire TV series in 4K on the phone in their pocket.
2020
Video calls become how the whole family — grandparents included — sees each other.
2022
ChatGPT launches — ordinary people start talking to an AI every day, about anything.
The point: the engine Datachecker runs on predates the iPhone, Wi-Fi, Google, cloud computing, and modern AI by decades. MapFlow is built on today's architecture — a browser-native, cloud-hosted PaaS — which is why it can do things Access structurally cannot. That is not a feature gap; it is a generational one.
The Genesis of MapFlow: Rooted in Operational Expertise
Built by a former Arcus data team leadI engineered MapFlow as a direct response to these persistent public sector infrastructure challenges, drawing on my four years of hands-on experience leading the Arcus data team. Having managed these data transitions firsthand, I purpose-built MapFlow's architecture to eliminate the chronic data integrity risks and generational vulnerabilities inherent to legacy configurations. This platform is the direct evolution of lessons learned on the front lines of UK data migration. It replaces fragile desktop tools with a secure, browser-isolated solution tailored specifically for public sector pressures.
4 years
Leading the Arcus data team
Front-line
Hands-on management of UK council data transitions
Purpose-built
Architecture engineered to fix legacy failure modes
While building MapFlow, the true scale of the systemic gap and the vast potential for a modern solution became completely apparent to me. The architectural difference and security leap that MapFlow offers turned out to be far greater than I ever imagined when I first commenced development. What started as a mission to fix specific network bugs evolved into a complete overhaul of how public sector data can be securely migrated.
How Enterprise IT Went Backwards
Data migrations once went forward — robust enterprise ETL pipelines carried National Highways assets and banking ledgers at scale. They have since been forced backwards, into a 1992-era desktop file format, by procurement frameworks that block modern, secure SaaS on certification technicalities while grandfathering the very tool it structurally cannot pass.
THE ENTERPRISE ERA
Sagent & Talend Pipelines
- High-volume handling
- Strict schema enforcement
- Full data lineage
THE REGRESSION
Bypassing Vetting with Access
- "Grandfathered" software
- Unencrypted local files
- 1992-era technology ceiling
THE SLEDGEHAMMER
MapFlow Zero-Trust PaaS
- Browser-isolated WASM
- Automated compliance
- Modern sovereign ETL
A Historical Timeline of Scale vs. Modern Stagnation
To understand why a modern solution is required, look at how enterprise data was successfully migrated in the past compared to the current reliance on legacy tools.
The Breaking Point
Streetworks Migration
Early encounters with Microsoft Access during critical Streetworks migrations exposed the hard technical ceilings of the Jet/ACE engine. The database could not cope with the relational complexity and transaction volumes, forcing a total abandonment of the GUI tool in favour of raw SQL scripting just to keep the migration alive.
The Enterprise Benchmark
National Highways
When scaling up to massive infrastructure projects, robust enterprise tools were the baseline. Approximately one-third of all National Highways Assets were successfully mapped, validated, and transferred using Sagent Data Flow, which handled high-volume geospatial and asset metadata without a single corruption event.
The Compliance Benchmark
Corporate Banking
In highly regulated banking environments where data lineage and security are legally mandated, the industry standard relied on heavy-duty integration engines like Talend. Security, auditing, and multi-user concurrency were treated as foundational requirements, not optional luxuries.
The Current Crisis: The "Poor Man of IT"
Despite decades of industry progress, many public sector and corporate migrations have actively regressed.
By forcing data teams to use MS Access simply because it is "free and grandfathered" into an old office license, organizations have become the "poor man in IT" — stuck on a 30-year-old technology platform that lacks an upgrade path, has no concept of REST APIs, and is structurally incompatible with modern cloud compliance.
We have entered a bizarre landscape where data specialists stream 4K video on their phones and utilize AI to draft emails, yet are forced to migrate millions of sensitive citizen records using a desktop file format launched in 1992 — before the invention of the smartphone, the smart speaker, or the modern web.
MapFlow was engineered specifically to break this deadlock — delivering the power of an enterprise ETL pipeline inside a secure, sovereign, browser-isolated package. The enterprise era's lineage and governance, restored on a modern PaaS, with zero CLOUD Act exposure.
Era / Paradigm Comparison Matrix
| Era / Paradigm | Core Technology | Scalability Ceiling | Security & Governance |
|---|---|---|---|
| The Enterprise Era (Asset & Banking Migrations) | Sagent Data Flow / Talend | High-volume data streams (e.g., 1/3 of National Highways Assets). | Full enterprise governance, data lineage, and audited transformation blocks. |
| The Modern Solution (Sovereign Cloud) | MapFlow | Cloud-scale processing with browser-isolated PostgreSQL 16 WASM engines. | Zero-Trust Blueprint. TPM 2.0 key binding, AES-256-GCM field encryption, and automated SIEM auditing. |
| The Modern Stagnation (The Regression Paradox) | Microsoft Access | Severe 2GB file limit. Prone to instant network corruption over modern VPNs. | Zero. Plaintext storage, no internal user access controls, no audit trail, and direct personal liability for data breaches. |
The LGR Multi-System Consolidation Matrix
LGR forces newly consolidated councils to run four or five conflicting legacy systems under one roof — a workload Microsoft Access structurally cannot consolidate. MapFlow is the answer: a single in-browser WASM staging layer that unifies every source into one Salesforce target.
The failure record — "lift and shift" is over
The public record shows what bare-bones cloud migrations produce, across every layer of municipal infrastructure.
Finance & ERP
Birmingham City Council
£140m Oracle Fusion overrun, 8,000 launch defects, Section 114 bankruptcy.
Finance & ERP
Hillingdon Council
EY disclaimed audit opinion on Oracle Fusion/EPM implementation.
Planning & Land Charges
Havant & Bracknell
Arcus SaaS go-live with planning history missing; stalled property sales.
Planning archive
Powys County Council
Idox migration collapsed the public register; 'service unavailable'.
Land Charges & GIS
South Oxfordshire & Vale
Planning↔land registry sync broke; manual cross-checking by staff.
Revenues, Benefits & Housing
Norwich City Council
Civica cloud migration abandoned after years of delays; legal settlement.
National oversight
MHCLG (June 2026)
Planning powers stripped from nine councils in one intervention.
Central government
Home Office / NLEDS
Police National Computer migration failures; PAC censure; mega-vendor dependence.
Sovereignty and operational stability are properties of architecture, not of contracts. When councils "lift and shift" data without mapping it first, the database relationships shatter. MapFlow is the inverse — the migration is engineered first, the data is cleansed and mapped before cutover, and sovereign AI learns the estate. Read the full evidence in the MapFlow white paper.
Field Mapping & Documentation
AI & Automation
In-Browser Pipeline Engine (PGLite vs MS Access)
AI Learning & Fine-Tuning
Governance & Collaboration
Salesforce Integration
Data Quality & Migration Timing
Training & Onboarding
Document Loading Workflow
Infrastructure & Scalability
Data Isolation & Sovereignty
Access Control & Governance
Automated Risk Mitigation
Security & Compliance
Defensive Posture & Evidence
Financial Sustainability & Risk Liability
Legacy Desktop File Architecture Constraints — Total Cost of Ownership
Acquisition price is one component of total cost of ownership; residual failure and regulatory costs are borne separately.
A desktop file database bundled into the corporate image carries an acquisition cost of £0. The residual costs — manual data reconstruction, remote-work downtime under documented SMB-over-VPN constraints, and UK GDPR regulatory exposure where Article 32 technical measures are omitted — are not reflected in that line item. Total cost of ownership must account for reconstruction labour, downtime, and regulatory liability, not acquisition price alone.
Acquisition cost
£0 — bundled into the Office image everyone already has.
Residual failure costs
Reconstruction labour, downtime under SMB-over-VPN packet-loss conditions, and Compact & Repair maintenance — billed in staff hours. Baseline: Microsoft KB Error 3343.
Regulatory liability
Plaintext, un-audited citizen data — accountability gap under UK GDPR Article 32 (omitted technical measures) and Article 33 (breach notification). Baseline: UK GDPR; ICO enforcement.
Summary
Key differences in plain language.
MapFlow vs Arcus Spreadsheet
- No version history — mappings get overwritten with no way to recover previous states.
- Sign-off is informal — email or verbal, with no traceable audit record.
- Sharing causes merge conflicts — multiple consultants editing the same spreadsheet.
- MapFlow replaces this with a structured, AI-assisted, version-controlled platform producing locked, signed-off artefacts.
MapFlow vs MS Access Datachecker
- Datachecker validates staged data pre-load; MapFlow catches issues at design time, before data is even staged.
- Datachecker requires a Windows client; MapFlow is fully browser-based.
- The Updater doesn't sync validation rules or triggers — both must be disabled manually before each load.
- The tools are complementary: MapFlow designs and governs; Datachecker can be used as a final post-load QA check.
MapFlow vs MS Access (pipeline engine)
- Access is a 30-year-old single-writer, file-locked, 2GB-ceiling engine that corrupts on network shares — MapFlow's in-browser PGLite is real Postgres 16 with no ceiling, no corruption, and concurrent tabs.
- Access encodes pipeline order in query names; MapFlow uses a declarative dependency graph with a topological runner and per-step logs.
- Not even air-gapped in practice: Arcus hands the .accdb to council IT, who park it on a network share and serve it over VPN — the exact workload Access corrupts under. MapFlow's Script Builder exports an offline runner for the one genuinely-disconnected-laptop case Access was built for.
- MapFlow's deterministic profiler + PII twins run as REAL full-table SQL against loaded data — Access's only 'model' is the operator eyeballing a datasheet.
Iteration Velocity
The speed gap between paradigms directly impacts delivery timelines.
The Arcus Loop — Typical cycle
- 1Mismatches between compiled SQL and live Salesforce config trigger batch faults.
- 2Resolving bugs requires manually refactoring Access forms, rewriting SQL, rebuilding staging tables.
- 3Validation rules and triggers not surfaced by Updater — must be disabled manually before each load.
- 4Each schema change restarts the cycle — no automated re-sync.
- 5Consultant knowledge held in memory or email, not a version-controlled artefact.
The MapFlow Loop — Faster iteration
- 1Salesforce schema changes picked up by re-running import — all fields update automatically.
- 2AI suggests revised mappings; consultant reviews and approves.
- 3New versioned snapshot created. Previous state preserved and restorable.
- 4Sign-off recorded in-platform. Updated mapping ready for next load cycle.
Cutover Recommendation
For a compressed weekend go-live window, MapFlow is the recommended choice.
- Large datasets (>2GB) require manual batch splitting — adds complexity during a tight window.
- Sequential processing means errors discovered late can extend resolution time.
- Schema changes discovered at go-time require Access expertise; cloud tools re-sync dynamically.
- Single-user desktop means coordination is manual when multiple issues arise simultaneously.
MapFlow advantages: automated schema sync handles configuration changes in real-time; cloud execution enables parallel processing; browser-based access allows the full team to collaborate during execution.
When to Use Each Tool
The tools serve different phases of the migration lifecycle.
MapFlow
Use from day one. Design, document, version, and govern all field mappings. Run AI profiling and PII scans. Generate UAT plans. Sign off mappings.
Arcus Spreadsheet
May be used as a starting point on existing projects. MapFlow can ingest existing mapping logic to accelerate the transition — but new projects should start in MapFlow.
MS Access Datachecker
Run to validate staged data before it is sent to Arcus for loading. Complements MapFlow — MapFlow ensures design is correct; Datachecker validates data conforms to SF rules.
SQL Server Tools
Standalone companion utility for exporting binary files from SQL Server to the file system and extracting RTF field content. Licensed separately — runs alongside MapFlow or independently.
Slack & Teams Bot
AI auto-replies to @Mapflow mentions in Slack channels and DMs. Teams channel polling. Support ticket notifications routed to Slack and Teams. Companion to MapFlow — not a standalone tool.
IDOX Uniform Tools
Dedicated suite for IDOX Uniform / Uniface migrations: DB Schema Scraper, PDF Documentation Scraper, Uniface Parser, and Screen Capture. Reverse-engineer legacy schemas and UI forms directly into MapFlow mappings.
InfoSec Technical Declarations
Architecture statements for council auditors.
Zero Persistence of Client Data
The US-parent orchestration platform (Base44) never persists client data — not plaintext, not even ciphertext. Ciphertext transits volatile memory (RAM) only during active pipelines and is never written to Base44 storage. Persistent ciphertext lives exclusively inside the UK-sovereign encrypted Postgres database. The orchestration layer is plumbing, not a data store, so a lawful US production order against it returns app metadata only.
Zero CLOUD Act Risk — UK-Sovereign by Design
The staging database and the AI inference layer are both UK-sovereign — UK-registered, UK-owned, with no US operations — bound only by UK domestic law (UK Companies Act 2006 / UK GDPR). A US CLOUD Act production order holds no authority over them. AI routes either to RelaxAI (UK data centres) or — for full air-gap sovereignty — to a local Ollama model on the operator's own machine (no network egress at all); the Sovereign Inference Shuttle keeps plaintext prompts and LLM keys on the Local Proxy in either path. Master keys are TPM-bound to the operator's hardware with a raw copy escrowed to the council's own corporate vault. The net posture: zero client data within US CLOUD Act reach, end to end.
Documented Hardware and Topology Vulnerabilities
Architectural and topological constraints of desktop file databases, each mapped to a verifiable source baseline.
Unmitigated regulatory risks under UK GDPR Article 33
The following are architectural constraints of the Jet/ACE desktop file database engine, not edge-case failures. Each is stated as an objective technical fact alongside its verifiable baseline.
Plaintext file architecture
The .accdb stores all values in plaintext. Without an encryption layer, file access equates to data access. Baseline: UK GDPR Article 32 ('state of the art' encryption requirement).
No application-layer authentication
The .accdb has no native login, RBAC, or session model. Access is governed entirely by host operating-system file permissions, which provide no per-record or per-field granularity. Baseline: NCSC Security Principle 2 (need-to-know access control).
No multi-factor or role-based access control
There is no TOTP, per-user role assignment, session timeout, or GeoIP gate. Windows network credentials are the sole control. Baseline: NIST SP 800-63B (authenticator assurance levels).
No tamper-evident audit logging
The format records no who/what/when. A breach investigation has no evidence base because none was captured. Baseline: NCSC Security Principle 3 (tamper-proof audit trails); UK GDPR Article 30 (records of processing).
Uninventoried copies complicate breach reporting
When .accdb files are distributed by email, USB, and RDP with no register, a lost device cannot be inventoried, which delays the Article 33 72-hour notification assessment. Baseline: UK GDPR Article 33 (breach notification).
No hardware key binding
Without TPM 2.0 or Secure Enclave key custody, a stolen device yields plaintext data with no key to break. Baseline: NIST SP 800-53 SC-12/13 (cryptographic key management and protection).
No cryptographic key lifecycle
There are no keys to rotate, escrow, or phase-destroy, so a per-environment key lifecycle cannot be implemented. Baseline: ISO 27001 Annex A.10 (cryptographic controls).
No AI inference surface
Jet/ACE and VBA predate modern AI; there is no inference path to keep sovereign. MapFlow routes AI to RelaxAI (UK data centres) or a local Ollama model via the Sovereign Inference Shuttle, keeping plaintext prompts and LLM keys on the Local Proxy. Baseline: MapFlow AI Residency configuration.
Format corruption under documented network conditions
The Jet/ACE file format corrupts under SMB lease contention and VPN packet loss. Microsoft documents database inconsistency under these conditions. Baseline: Microsoft Knowledge Base Error 3343 ('Database is in an inconsistent state').
No tamper-evident evidence ledger
A flat .accdb has no hash-chained attestation ledger, no off-platform SIEM mirror, no source-table fingerprints, and no run correlation IDs. Disputes cannot be resolved against immutable backend logs. Baseline: UK GDPR Article 5(2) (accountability).
Baseline summary: encryption at rest, hardware-bound keys, MFA, RBAC, audit trails, a single tracked copy, and a per-environment key lifecycle are the control set a modern migration is required to meet (UK GDPR Article 32; NCSC Principles 2 and 3; NIST SP 800-63B). A desktop file database does not implement these controls by design. The technical control matrix below states each control as an objective fact against its source baseline.
Technical Control Matrix
Objective architectural controls, each mapped to a verifiable source baseline. Statements describe technical facts, not commercial judgements.
No file to mis-deploy
The "we secured it and broke it" failure class, eliminated by design.
The Core Challenge: Securing Legacy Databases on Modern Networks
Local government Information Security (InfoSec) teams face an impossible balancing act when managing legacy file-based databases like Microsoft Access. The traditional security controls required to protect citizen data directly conflict with how these legacy database engines operate.
The Security Imperative
InfoSec teams must enforce zero-tolerance policies for citizen data. This means ensuring robust access control, automated backups, centralized antivirus scanning, and secure remote access via VPNs. Storing data on a single, disconnected endpoint is a major compliance risk.
The Technical Friction
Legacy engines (like Jet/ACE) were designed for local machine environments, not distributed networks. When moved to network shares or accessed over VPNs via Server Message Block (SMB) protocols, the high volume of file-locking traffic often causes severe latency and database corruption.
The Structural Paradox
In this scenario, standard, well-intentioned compliance measures accidentally degrade system stability. The engineering limits of the legacy software force a trade-off between data security and operational viability — there is no deployment pattern in which Access is both approved by InfoSec and performs acceptably, because the two states are mutually exclusive.
Documented Failure Modes — Standard InfoSec Practise vs MS Access
These are not theoretical risks — they are well-documented, vendor-acknowledged failure patterns that recur whenever a file-based database engine meets a modern corporate network.
1. The Official Microsoft Core Flaw — "The SMB Leases Bug"
The Evidence: Microsoft's own official Knowledge Base documentation (Error 3343 / "Database is in an inconsistent state").
The Failure: Microsoft openly documented that when a Windows network file server utilizes "SMB Leases" to optimize network traffic, it completely breaks the Microsoft Access Jet/ACE file-locking protocol.
The Project Failure: When multiple users connect to a shared network drive, the server tries to "lease" chunks of the file to individual laptops to save bandwidth. The moment two users write data simultaneously, the server drops the lease, Access panics, and the database file permanently corrupts. Microsoft's only permanent recommendation for enterprise networks is a clunky server registry hack to disable network optimization entirely.
2. The Remote-Work "VPN Packet Drop" Epidemic
The Evidence: Documented across enterprise IT forums — ServerFault, SuperUser, Microsoft Q&A — tens of thousands of logged project failures matching this exact template.
The Failure: During mass transitions to remote work, companies globally migrated desktop database backends onto secure network file shares so remote teams could connect via VPN.
The Project Failure: VPNs prioritize encryption over continuous data streaming, leading to tiny, normal network packet drops. While a packet drop causes a web page to simply reload, it leaves an Access network file lock (.laccdb) permanently stuck open. This creates an instant "Unrecognized Database Format" error, locking out entire teams and forcing corporate IT to completely scrap remote access projects due to unfixable data corruption.
3. The Enterprise Antivirus "Lockout" Wave
The Evidence: Documented widely by enterprise endpoint management platforms (CrowdStrike, Symantec, Microsoft Defender).
The Failure: Corporate InfoSec mandates require that all shared network drives undergo real-time, continuous antivirus scanning.
The Project Failure: Access is a passive file, not an active database server. Running a heavy query forces massive streams of raw file data across the corporate network. The automated antivirus software flags this sudden, massive file-reading activity as a ransomware signature or malware attack. The security scanner locks the file mid-write to scan it. This sudden security lock forces a hard disconnect while users are saving data, instantly shredding the database file.
The MapFlow Approach: Compliance and Performance by Design
MapFlow resolves this conflict by aligning natively with modern enterprise security standards, removing the need for high-risk workarounds.
- Native Access Control & Auditability:Identity management, role-based access controls (RBAC), and full audit logging are built directly into the application layer, satisfying governance requirements immediately.
- Modern Cloud-Native Architecture:Because the platform does not rely on fragile file-sharing protocols, it maintains high performance and data integrity across remote connections and VPNs.
- Inherent Data Sovereignty:Security boundaries, automated backups, and data residency rules are integrated into the core design, ensuring InfoSec standards are met without compromising the user experience.
UK Regulatory Position — ICO & NCSC
UK regulatory bodies, including the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC), require that personal data processing involves "appropriate technical or organisational measures" (UK GDPR Article 5(1)(f)). Standalone MS Access files often fail these standards, as they lack robust "state of the art" encryption (Article 32), fail to ensure "need-to-know" access control (NCSC Principle 2), and do not provide "tamper-proof audit trails" (NCSC Principle 3). You can read the full guidance on the official websites of the ICO and the NCSC.
Governance Requirements for Sanctioning MS Access
To formally sanction the use of Microsoft Access (.accdb) for sensitive personal data when a compliant alternative exists, the Council must complete the following mandatory internal governance steps, framed against the statutory baseline:
- 1Mandatory Legal DPIA: A formal Data Protection Impact Assessment (Article 35 UK GDPR) must be completed, explicitly documenting the technical constraints of the candidate tool regarding encryption, audit trails, and access controls.
- 2Formal DPO Consultation: The Council's independent Data Protection Officer (DPO) must review the DPIA and record the residual risk finding, particularly where a viable compliant alternative exists.
- 3Corporate Risk Register Entry: The residual risk must be escalated and logged on the Council's Strategic Corporate Risk Register, noting the potential for regulatory fines and loss of public trust.
- 4IAO and SIRO Sign-off: The Information Asset Owner (IAO) and the Senior Information Risk Owner (SIRO) must sign the risk acceptance log.
- 5Statutory Accountability under Section 198, Data Protection Act 2018: Under Section 198 of the UK Data Protection Act 2018, corporate officers carry personal accountability for organisational data infractions if the technical measures outlined in UK GDPR Article 32 (such as encryption and access control) are omitted. Documenting and implementing those measures is the governance step that discharges that accountability. MapFlow UK aligns directly with these requirements by implementing automated, tamper-evident SIEM logging, AES-256-GCM field encryption, and hardware-bound key custody.
Inconsistency in Vetting Standards: The MS Access Exception
A critical contradiction exists in the Council's current security vetting process.
If Microsoft Access were evaluated as a standalone database software — unbundled from the pre-approved Microsoft Office desktop package — it would be instantly rejected by Procurement and InfoSec.
Standard Access (.accdb) files are not architected to implement the controls required for certification against ISO 27001, SOC 2, or NIST baselines:
No Security Control Alignment
A standalone Access file lacks the structural framework required to map against ISO 27001, SOC 2, or NIST controls. It cannot enforce multi-factor authentication (MFA), role-based access control (RBAC), or automated, tamper-proof audit logging.
Bundled-Image Pre-Approval
MS Access is admitted within the Council through its inclusion in the standard Microsoft Office desktop image, rather than through a standalone security assessment against the controls above. A standalone evaluation against those controls would be the neutral baseline.
Conclusion
Assessing an accredited platform and a legacy desktop file against the same control set is the neutral baseline. Applying a certification barrier to one tool while admitting an uncertified legacy file through the desktop image creates an accountability gap under the UK GDPR Accountability Principle (Article 5(2)).
The Regulatory Deadlock
A structural outcome exists in the current framework. Modern, cloud-native Extract, Transform, Load (ETL) Software-as-a-Service (SaaS) platforms are procedurally blocked where US CLOUD Act exposure cannot be resolved, which routes vendors toward the legacy desktop file database as the default option. Conversely, the cost of developing a sovereign alternative from scratch and achieving independent, third-party audited security accreditations (ISO 27001, Cyber Essentials Plus) is commercially prohibitive for small-to-medium enterprises. The net effect is that an uncertified legacy desktop engine is admitted through the desktop image while accredited cloud-native platforms are blocked on certification grounds — an asymmetry that constrains the adoption of architecturally secure alternatives and leaves residual UK GDPR exposure on the legacy path. Stating this asymmetry is a factual observation of the framework's operation, not a commercial judgement of any vendor.
The Accredited Platform: MapFlow Is Not the Barrier
MapFlow does not run on unvetted infrastructure. The platform-as-a-service (PaaS) layer that hosts, orchestrates, and secures MapFlow — Base44 — is an independently accredited, enterprise-grade platform that has already passed the security audits the framework requires. The accreditation cited as a precondition has, in substance, already been discharged by the platform beneath it.
Because the underlying PaaS carries its own accreditation, the residual certification gap cited against MapFlow is a procedural matter rather than a security concern. The neutral baseline is that an accredited platform and a legacy desktop file should be assessed against the same control set. MapFlow is not the obstacle to citizen-data security; the obstacle is a framework that assesses an accredited platform against controls a legacy file was never asked to meet.
A Replacement, Not a Competitor — Why MapFlow Exists
MapFlow was designed from the outset as a direct replacement for the MS Access Datachecker — not a rival product seeking to displace a weak incumbent. To be clear about the baseline: Datachecker is a genuinely good product. It has served councils reliably for years, and the team behind it built something that works far better than the underlying technology should allow. The problem is not effort or craft; it is that Datachecker is built on a 30-year-old desktop file database engine, and there is no realistic path to materially improve it within that architecture. The ceiling is fixed by Microsoft Access itself, not by the people who maintain it.
Committing to build a modern replacement is, commercially, exceptionally difficult to justify under current conditions. Over the last decade, public sector procurement frameworks have increasingly treated data migration as a low-cost commodity. This approach often overlooks the critical architectural differences between legacy systems and modern, secure data pipelines.
Human Capital and Resource Constraints
The legacy architecture framework creates a significant barrier to talent acquisition and team retention. In the modern technology landscape, skilled data professionals actively prioritize projects that utilize current, cloud-native toolsets to maintain their market relevance. Forcing engineering teams to rely on outdated desktop database structures creates a severe recruitment bottleneck, as qualified practitioners are hesitant to allocate their career development to legacy environments. This challenge is further intensified by procurement models that treat data migration as a low-cost commodity. By deflating the realistic budgets required to secure specialized data talent, public bodies face a continuous cycle of staff turnover and critical skill shortages, directly introducing delivery risks to complex migration projects.
That calculation leaves only boutique, single-operator specialists as the realistic people to develop a tool like this — they are the only ones whose cost base and focus can absorb a multi-year build for a market that procurement has priced as a commodity. Yet those same specialists are precisely the ones structurally unable to clear the full certification stack a procurement framework demands. The result is a market with no natural supplier: the incumbent cannot evolve past its 30-year-old architecture, the scale players cannot justify the build against the collapsed fee, and the specialists who can build it cannot afford the badges. MapFlow exists because of the combination of 30 years of experience — mostly in data transfers, including non-SaaS-based ETL solutions where available — and the extreme velocity of development that can be attained using the PaaS called Base44.
Proactive Security, Not Reactive
MapFlow's security is continuously verified across three tiers — a posture no legacy tool can match.
Roboshadow — Endpoint & App Monitoring
Roboshadow continuously scans operator endpoints and the MapFlow application for vulnerabilities, patch status, and configuration drift — detecting and remediating weaknesses before they can be exploited. MS Access and spreadsheets have no equivalent: a corrupted .accdb file or an unpatched laptop is a silent risk until something breaks.
Independent Security Audit (2026-08-27)
An internal audit identified three MFA findings — plaintext TOTP secrets, base64 backup codes, no rate limiting — all now fixed: secrets AES-256-GCM encrypted at rest, backup codes SHA-256 salted-hashed, 5-attempt lockout with 15-min cooldown. The full audit reference is published on the Independent Security Audit page.
Ready to move beyond spreadsheets?
MapFlow replaces the manual spreadsheet workflow with a structured, AI-assisted platform that produces traceable, signed-off mapping artefacts.